suse · CVE-2017-5226

Quick triage

Priority: high Published: 2021-05-30 13:52:05 UTC Updated: 2026-04-18 15:45:06 UTC

View at Official suse advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2017-5226 severity important: SUSE including 99 source package names (bubblewrap, bubblewrap-0.11.0-150500.3.9.1, …), 125 product×package rows across 27 product lines (SUSE Linux Enterprise High Performance Computing 12 SP5, SUSE Linux Enterprise High Performance Computing 15-LTSS, … (27 product lines)): Fixed 110, Known Not Affected 15.

Description:

When executing a program via the bubblewrap sandbox, the nonpriv session can escape to the parent session by using the TIOCSTI ioctl to push characters into the terminal's input buffer, allowing an attacker to escape the sandbox.

cvelogic Threat Intelligence